Malware

Generic.Keylogger.2.3A23371F malicious file

Malware Removal

The Generic.Keylogger.2.3A23371F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.3A23371F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Keylogger.2.3A23371F?


File Info:

crc32: 0D23FA04
md5: a1fc4f4f5d3fc0766dd69dd332125fd2
name: 00.exe
sha1: fa5e86460ecd2bd96a8b0337cc275921aa08a601
sha256: c7d6dc4da57ced856f14cb2d0cf41f213fb4afbd7c1592ee5bd6c797f06a1a62
sha512: 08ae1fb605c993d4a913520a8fb6651264ff3634213ceb93e92ba6f3fb3e6039a7defd2cc4532b8d1d8f375b5014197d926559523f5b7b42f36323476b70412d
ssdeep: 6144:JkcYaKV61WgPFFUD2SySE/W4onbEQZRydl/tdBpI6XxKjiooS:J7YaKwIgN+D2fzjonwxlFFIeDooS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Keylogger.2.3A23371F also known as:

MicroWorld-eScanDeepScan:Generic.Keylogger.2.3A23371F
FireEyeGeneric.mg.a1fc4f4f5d3fc076
CAT-QuickHealTrojan.Generic
McAfeeArtemis!A1FC4F4F5D3F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055d4871 )
BitDefenderDeepScan:Generic.Keylogger.2.3A23371F
K7GWTrojan ( 0055d4871 )
Cybereasonmalicious.f5d3fc
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Keylogger.Deepscan-7603977-0
GDataWin32.Trojan-Spy.Keylogger.FTYYZ6
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Zegost.32d83fb3
NANO-AntivirusTrojan.Win32.Farfli.getkjn
ViRobotTrojan.Win32.Z.Farfli.382464.A
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10b9c325
Ad-AwareDeepScan:Generic.Keylogger.2.3A23371F
SophosMal/Generic-S
ComodoMalware@#31qz09j1e7i3j
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Rootkit.22030
TrendMicroTROJ_GEN.R002C0DF720
McAfee-GW-EditionBehavesLike.Win32.PWSSpyeye.fc
EmsisoftDeepScan:Generic.Keylogger.2.3A23371F (B)
IkarusPacked.Win32.Hrup
JiangminBackdoor.Generic.bafy
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Zegost
Endgamemalicious (high confidence)
ArcabitDeepScan:Generic.Keylogger.2.3A23371F
AegisLabTrojan.Win32.Generic.lt5d
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.gen!B
CynetMalicious (score: 90)
BitDefenderThetaGen:NN.ZexaF.34128.xmGfaCYMuUib
ALYacDeepScan:Generic.Keylogger.2.3A23371F
MAXmalware (ai score=80)
VBA32Trojan.Rootkit
MalwarebytesBackdoor.Farfli
ESET-NOD32a variant of Win32/Farfli.CTT
TrendMicro-HouseCallTROJ_GEN.R002C0DF720
RisingBackdoor.Zegost!8.177 (CLOUD)
YandexTrojan.Farfli!zvt8iIRJWHo
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.319CC8!tr
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.aec

How to remove Generic.Keylogger.2.3A23371F?

Generic.Keylogger.2.3A23371F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment